CVE-2014-9708: Embedthis Appweb

Medium severity, CVSS 5.0. EPSS: 56.2% chance of exploitation in the next 30 days.

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

Affected products

  • Embedthis Appweb: before 4.6.6 (fixed in 4.6.6); from 5.0.0, before 5.2.1 (fixed in 5.2.1)
  • Juniper Junos: version 12.1x46 only; version 12.3x48 only; version 15.1x49 only; version 12.3 only; version 15.1 only; version 15.1x53 only; …
  • Oracle Enterprise Communications Broker: up to and including 2.0.0

Published 2015-03-31. Last modified 2026-06-17.